URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-04-27 11:28:55 | 125.253.93.186 | cs51.koneksiaman.net | Not listed | AS59210 PHOENIXNAP-AS-SG1 | SG | yes |
| 2025-05-03 10:11:44 | 103.253.215.19 | Not listed | AS58487 CRI-AS-AP | ID | no | |
| 2021-11-07 09:46:24 | 131.153.99.18 | cs30.koneksiaman.net | Not listed | AS59210 PHOENIXNAP-AS-SG1 | SG | no |
| 2021-01-26 16:49:11 | 63.251.125.5 | Not listed | AS14636 INTERNAP-BLK4 | US | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2021-01-26 16:49:12 | https://goldcake.co.id/pn892f.zip | Offline | Dridex |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2021-11-09 12:39:57 | 2d0066273a65fd326d459caf26be43c274d7b10a15e3bdc4488a79e8732626c8 | dll | ||
| 2021-11-09 12:19:54 | 67a0286d4680968a0e0cc0c22c996fdc1ef21fc0898172d524d36a9a859a8fb1 | dll | ||
| 2021-01-26 16:49:10 | 26bf46b79aeb7775dbf7ccef58f5becb631ac14591ec9e1cdad6962600db5bc6 | dll | Dridex |
SG
ID
US